Назад
обновлено 3 часа назад

Supplier Security & Assurance, Security GRC (AI)

255 000 - 270 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Supplier Security & Assurance, Security GRC (AI): Running end-to-end supplier security assessments and continuous monitoring for SaaS, software, data operations, infrastructure, hardware, and services vendors with an accent on residual risk, remediation, contractual controls, and evidence review. Focus on tuning Claude-powered assessment workflows, evaluating SOC 2 and penetration-test evidence, detecting configuration and scope drift, and driving supplier findings to closure.

Location: San Francisco, CA; Seattle, WA; New York City, NY; or Washington, DC. Hybrid policy: staff are expected to work from one of the offices at least 25% of the time, with some roles requiring more office attendance.

Annual salary: $255,000–$270,000 USD.

Company

Anthropic develops reliable, interpretable, and steerable AI systems intended to be safe and beneficial for users and society.

What you will do

  • Run supplier security assessments end to end, reviewing evidence, validating agent-drafted evaluations, determining inherent and residual risk, and routing specialized findings to domain reviewers.
  • Manage supplier findings and risk treatment by assigning severity, owners, and due dates, driving remediation, recording risk acceptances, and escalating open issues to the risk register.
  • Operate continuous monitoring and trigger reassessments for changes in data classification, SOC 2 reports, subprocessors, vendor incidents, SaaS configuration, data, or use cases.
  • Improve supplier security coverage, questionnaires, requirements, tooling, and program roadmaps.
  • Tune the Claude-powered assessment platform through prompt development, questionnaire design, calibration, and output quality assurance.
  • Contribute to KPI and KRI reporting on coverage, cycle time, residual risk, open issues, and reassessments.

Requirements

  • Experience running supplier security assessments at a technology company, including scoping, control and evidence review, residual risk documentation, and findings closure.
  • Working knowledge of inherent and residual risk, control effectiveness, compensating controls, and risk acceptance.
  • Experience driving risk treatment across teams and operating issue management workflows with owners, due dates, remediation tracking, and escalation.
  • Experience building or tuning an LLM-backed workflow, agent, or automation, including prompt tuning and model-output review.
  • Technical knowledge of SaaS security configuration, including SSO, SCIM, administrative scoping, sharing defaults, and audit-log export.
  • Ability to interpret SOC 2 reports and penetration tests, including control exceptions, carve-outs, complementary user entity controls, and evidence limitations.

Nice to have

  • Experience assessing cloud infrastructure, data center, data-pipeline, human data operations, hardware, compute, or neocloud vendors.
  • Experience supporting SOX, SOC 2, or ISO 27001 third-party or vendor-management controls.
  • Experience with post-approval monitoring, shadow IT and SaaS detection, vendor incident management, vendor audits, or site visits.

Culture & Benefits

  • Collaborative environment focused on high-impact AI research and trustworthy, steerable AI.
  • Competitive compensation with optional equity donation matching.
  • Generous vacation and parental leave.
  • Flexible working hours and office-based collaboration.
  • Visa sponsorship is available, with reasonable efforts and immigration-lawyer support for candidates receiving an offer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →